The Turla cyber group backdoor allows for the takeover of Microsoft Exchange servers.

ESET has conducted an analysis of the malware LightNeuron, which is used by members of the notorious cybercriminal group Turla.

The Turla cyber group backdoor allows for the takeover of Microsoft Exchange servers.

The hacker group Turla gained notoriety back in 2008 after hacking into the Central Command network of the United States Armed Forces. The cybercriminals aim to steal sensitive data of strategic importance.

In recent years, Turla's actions have affected hundreds of users in over 45 countries, including government and diplomatic institutions, military, educational, and research organizations, among others.

Now, let's return to the malware LightNeuron. This backdoor allows near-complete control over email. servers Microsoft Exchange. By gaining access to the Microsoft Exchange transport agent, the attackers can read and block emails, replace attachments and edit text, as well as compose and send messages on behalf of the organization's employees.


The Turla cyber group backdoor allows for the takeover of Microsoft Exchange servers.

Malicious activity is hidden within specially crafted PDF documents and JPG images; communication with the backdoor is carried out by sending requests and commands through these files.

ESET specialists note that cleaning a system of the LightNeuron malware presents quite a complex challenge. The thing is, deleting the malicious files does not yield results and can lead to disruptions in the functionality of Microsoft Exchange.

There are reasons to believe that this backdoor is also used for Linux systems. 



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster